Expires soon Ernst & Young

GDS Consulting_TPRM Consultant

  • PHILIPPINES
  • Teaching

Job description

Third Party Risk Management (TPRM) – Consultant

The Opportunity

·  Staff in the Risk Advisory team to work on various TPRM projects for our customers across the globe.
·  You will be responsible for delivering on accounts in accordance with EY quality guidelines & methodologies. You will need to execute and coordinate on accounts and relationships on a day-to-day basis and explore new business opportunities for the firm. Establishing, strengthening and nurturing relationships with clients and internally across service lines and proactively will also be a part of your day-to-day activities. You will assist in developing new methodologies and internal initiatives, and help in creating a positive learning culture by coaching, counselling and developing junior team members.
·  In line with EY’s commitment to quality, you’ll confirm that work is of the highest quality as per EY’s quality standards, by reviewing the work provided by junior members.

Key Responsibilities

·  Assist Managers in the delivery of third party risk management engagements, such engagements involve performing a security assessment of a client’s third party service providers. This includes:
·  Performing security assessments of new and existing service providers
·  Performing vendor assessment reviews leveraging a SIG Lite or Full SIG
·  Verifying that all required SIG (Lite) questions have been answered by vendor and all required documentation has been received
·  Assessing vendor answers and follow up with vendor directly for questions
·  Conducting a risk analysis and assessment of vendor information and documentation against a client’s IT security and data privacy requirements
·  Identifying whether additional information should be obtained from the vendor
·  Defining appropriate risk levels and corrective actions
·  Identifying issues and work with vendor to resolve/accept
·  Following up on corrective action plans
·  Maintaining issues/items tracker and status updates for each vendor review.
·  Provide risk acceptance and/or risk remediation recommendations
·  Provide guidance and share knowledge with team members and participate in performing procedures focusing on complex, judgmental and/or specialized issues.
·  Maintain relationships with client management to manage expectations of service, including work products, timing, and deliverables. Demonstrate a thorough understanding of complex information systems and apply it to client situations
·  Use extensive knowledge of the client's business/industry to identify technological developments and evaluate impacts on the client's business. Demonstrate strong project management skills, inspire teamwork and responsibility with engagement team members, and use current technology/tools to enhance the effectiveness of deliverables and services. Understand EY and its service lines and actively assess what the firm can deliver to serve clients
·  Supervise the delivery of the engagement against the engagement budget, timeline, and scope
·  Perform quality assurance reviews
·  Provide coaching and guidance to the assessment team members
·  Assist in creating innovative insights for clients, adapt methods & practices to fit operational team needs, contribute to thought leadership documents and develop new methodologies.
·  Facilitate discussions / knowledge sharing with key client personnel and contribute to EY thought leadership.
·  Plan & deliver on client engagements. Provide regular status updates on engagements and work products.
·  Demonstrate strong project management skills
·  Maintain a strong client focus by effectively serving client needs and developing productive working relationships with client personnel. Stay abreast of current business and economic developments and new pronouncements/standards relevant to the client's business.
·  Demonstrate industry expertise (deep understanding of the industry, emerging trends, issues/challenges, key players & leading practices)
·  Review status updates and prepare management presentations/audit committee presentations etc.
·  Actively contribute to improving operational efficiency on projects & internal initiatives.

  

Qualifications

·  Bachelor’s Degree in Information Assurance, or other Risk Management practice desired
·  0 - 1 year of experience in cyber security or third party risk management
·  Knowledge of various assessment types (e.g., self-assessments, audits, vulnerability assessments, penetration tests, third-party assurance)
·  Understanding of key industry control frameworks (NIST Cyber Security Framework, COSO, COBIT, ISO 27000, Unified Compliance Framework, etc.)
·  Understanding of Information Security policies and standards
·  Knowledge and understanding of systems architecture, infrastructure, security and applications
·  Strong analytical capabilities
·  Excellent communications skills
·  Ability to communicate basic Information Security Risk assessment information to non-technical business leaders to ensure they comprehend the risk being assigned to them.
·  Able to effectively communicate evaluation of risk remediation plans to action plan owners to ensure that mitigation activities are appropriately addressed
·  Knowledge on business processes and their relationship to technology

 

What we look for

 

·  A Team of people with commercial acumen, technical experience and enthusiasm to learn new things in this fast-moving environment with consulting skills.
·  An opportunity to be a part of market-leading, multi-disciplinary team of 1400 + professionals, in the only integrated global transaction business worldwide.
·  Opportunities to work with EY Consulting practices globally with leading businesses across a range of industries.

 

What working at EY offers

 

At EY, we’re dedicated to helping our clients, from start–ups to Fortune 500 companies — and the work we do with them is as varied as they are.

You get to work with inspiring and meaningful projects. Our focus is education and coaching alongside practical experience to ensure your personal development. We value our employees and you will be able to control your own development with an individual progression plan. You will quickly grow into a responsible role with challenging and stimulating assignments. Moreover, you will be part of an interdisciplinary environment that emphasizes high quality and knowledge exchange. Plus, we offer:

 

·  Support, coaching and feedback from some of the most engaging colleagues around.
·  Opportunities to develop new skills and progress your career.
·  The freedom and flexibility to handle your role in a way that’s right for you.

 

About EY

As a global leader in Assurance, Tax, Strategy & transactions and Consulting services, we’re using the finance products, expertise and systems we’ve developed to build a better working world. That starts with a culture that believes in giving you the training, opportunities andcreativefreedom to make things better.Whenever you join, however long you stay, the exceptional EY experience lasts a lifetime.And with a commitment to hiring and developing the most passionate people, we’ll make our ambition to be the best employer by 2020 a reality.

If you can confidently demonstrate that you meet the criteria above, please contact us as soon as possible.

Join us in building a better working world. 

Apply now.

 

Third Party Risk Management (TPRM) – Consultant

The Opportunity

·  Staff in the Risk Advisory team to work on various TPRM projects for our customers across the globe.
·  You will be responsible for delivering on accounts in accordance with EY quality guidelines & methodologies. You will need to execute and coordinate on accounts and relationships on a day-to-day basis and explore new business opportunities for the firm. Establishing, strengthening and nurturing relationships with clients and internally across service lines and proactively will also be a part of your day-to-day activities. You will assist in developing new methodologies and internal initiatives, and help in creating a positive learning culture by coaching, counselling and developing junior team members.
·  In line with EY’s commitment to quality, you’ll confirm that work is of the highest quality as per EY’s quality standards, by reviewing the work provided by junior members.

Key Responsibilities

·  Assist Managers in the delivery of third party risk management engagements, such engagements involve performing a security assessment of a client’s third party service providers. This includes:
·  Performing security assessments of new and existing service providers
·  Performing vendor assessment reviews leveraging a SIG Lite or Full SIG
·  Verifying that all required SIG (Lite) questions have been answered by vendor and all required documentation has been received
·  Assessing vendor answers and follow up with vendor directly for questions
·  Conducting a risk analysis and assessment of vendor information and documentation against a client’s IT security and data privacy requirements
·  Identifying whether additional information should be obtained from the vendor
·  Defining appropriate risk levels and corrective actions
·  Identifying issues and work with vendor to resolve/accept
·  Following up on corrective action plans
·  Maintaining issues/items tracker and status updates for each vendor review.
·  Provide risk acceptance and/or risk remediation recommendations
·  Provide guidance and share knowledge with team members and participate in performing procedures focusing on complex, judgmental and/or specialized issues.
·  Maintain relationships with client management to manage expectations of service, including work products, timing, and deliverables. Demonstrate a thorough understanding of complex information systems and apply it to client situations
·  Use extensive knowledge of the client's business/industry to identify technological developments and evaluate impacts on the client's business. Demonstrate strong project management skills, inspire teamwork and responsibility with engagement team members, and use current technology/tools to enhance the effectiveness of deliverables and services. Understand EY and its service lines and actively assess what the firm can deliver to serve clients
·  Supervise the delivery of the engagement against the engagement budget, timeline, and scope
·  Perform quality assurance reviews
·  Provide coaching and guidance to the assessment team members
·  Assist in creating innovative insights for clients, adapt methods & practices to fit operational team needs, contribute to thought leadership documents and develop new methodologies.
·  Facilitate discussions / knowledge sharing with key client personnel and contribute to EY thought leadership.
·  Plan & deliver on client engagements. Provide regular status updates on engagements and work products.
·  Demonstrate strong project management skills
·  Maintain a strong client focus by effectively serving client needs and developing productive working relationships with client personnel. Stay abreast of current business and economic developments and new pronouncements/standards relevant to the client's business.
·  Demonstrate industry expertise (deep understanding of the industry, emerging trends, issues/challenges, key players & leading practices)
·  Review status updates and prepare management presentations/audit committee presentations etc.
·  Actively contribute to improving operational efficiency on projects & internal initiatives.

  

Qualifications

·  Bachelor’s Degree in Information Assurance, or other Risk Management practice desired
·  0 - 1 year of experience in cyber security or third party risk management
·  Knowledge of various assessment types (e.g., self-assessments, audits, vulnerability assessments, penetration tests, third-party assurance)
·  Understanding of key industry control frameworks (NIST Cyber Security Framework, COSO, COBIT, ISO 27000, Unified Compliance Framework, etc.)
·  Understanding of Information Security policies and standards
·  Knowledge and understanding of systems architecture, infrastructure, security and applications
·  Strong analytical capabilities
·  Excellent communications skills
·  Ability to communicate basic Information Security Risk assessment information to non-technical business leaders to ensure they comprehend the risk being assigned to them.
·  Able to effectively communicate evaluation of risk remediation plans to action plan owners to ensure that mitigation activities are appropriately addressed
·  Knowledge on business processes and their relationship to technology

 

What we look for

 

·  A Team of people with commercial acumen, technical experience and enthusiasm to learn new things in this fast-moving environment with consulting skills.
·  An opportunity to be a part of market-leading, multi-disciplinary team of 1400 + professionals, in the only integrated global transaction business worldwide.
·  Opportunities to work with EY Consulting practices globally with leading businesses across a range of industries.

 

What working at EY offers

 

At EY, we’re dedicated to helping our clients, from start–ups to Fortune 500 companies — and the work we do with them is as varied as they are.

You get to work with inspiring and meaningful projects. Our focus is education and coaching alongside practical experience to ensure your personal development. We value our employees and you will be able to control your own development with an individual progression plan. You will quickly grow into a responsible role with challenging and stimulating assignments. Moreover, you will be part of an interdisciplinary environment that emphasizes high quality and knowledge exchange. Plus, we offer:

 

·  Support, coaching and feedback from some of the most engaging colleagues around.
·  Opportunities to develop new skills and progress your career.
·  The freedom and flexibility to handle your role in a way that’s right for you.

 

About EY

As a global leader in Assurance, Tax, Strategy & transactions and Consulting services, we’re using the finance products, expertise and systems we’ve developed to build a better working world. That starts with a culture that believes in giving you the training, opportunities andcreativefreedom to make things better.Whenever you join, however long you stay, the exceptional EY experience lasts a lifetime.And with a commitment to hiring and developing the most passionate people, we’ll make our ambition to be the best employer by 2020 a reality.

If you can confidently demonstrate that you meet the criteria above, please contact us as soon as possible.

Join us in building a better working world. 

Apply now.

Make every future a success.
  • Job directory
  • Business directory